CVE-2019-14362
28.07.2019, 18:15
Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal. This vulnerability could allow remote authenticated attackers to replace a file on the server via the getAttachmentDirectoryForNewAttachment inpKey value.
Vendor | Product | Version |
---|---|---|
openbravo | openbravo_erp | 3.0 |
openbravo | openbravo_erp | 3.0:maintenance_pack0.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack1 |
openbravo | openbravo_erp | 3.0:maintenance_pack10 |
openbravo | openbravo_erp | 3.0:maintenance_pack10.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack10.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack10.3 |
openbravo | openbravo_erp | 3.0:maintenance_pack11 |
openbravo | openbravo_erp | 3.0:maintenance_pack11.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack12 |
openbravo | openbravo_erp | 3.0:maintenance_pack12.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack12.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack13 |
openbravo | openbravo_erp | 3.0:maintenance_pack13.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack13.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack14 |
openbravo | openbravo_erp | 3.0:maintenance_pack14.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack14.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack15 |
openbravo | openbravo_erp | 3.0:maintenance_pack15.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack15.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack16 |
openbravo | openbravo_erp | 3.0:maintenance_pack16.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack16.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack16.3 |
openbravo | openbravo_erp | 3.0:maintenance_pack17 |
openbravo | openbravo_erp | 3.0:maintenance_pack17.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack17.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack17.3 |
openbravo | openbravo_erp | 3.0:maintenance_pack18 |
openbravo | openbravo_erp | 3.0:maintenance_pack18.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack18.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack18.3 |
openbravo | openbravo_erp | 3.0:maintenance_pack18.4 |
openbravo | openbravo_erp | 3.0:maintenance_pack18.5 |
openbravo | openbravo_erp | 3.0:maintenance_pack19 |
openbravo | openbravo_erp | 3.0:maintenance_pack19.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack19.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack19.3 |
openbravo | openbravo_erp | 3.0:maintenance_pack19.4 |
openbravo | openbravo_erp | 3.0:maintenance_pack2 |
openbravo | openbravo_erp | 3.0:maintenance_pack2.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack2.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack2.3 |
openbravo | openbravo_erp | 3.0:maintenance_pack2.4 |
openbravo | openbravo_erp | 3.0:maintenance_pack20 |
openbravo | openbravo_erp | 3.0:maintenance_pack21 |
openbravo | openbravo_erp | 3.0:maintenance_pack21.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack22 |
openbravo | openbravo_erp | 3.0:maintenance_pack22.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack22.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack22.3 |
openbravo | openbravo_erp | 3.0:maintenance_pack23 |
openbravo | openbravo_erp | 3.0:maintenance_pack23.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack23.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack24 |
openbravo | openbravo_erp | 3.0:maintenance_pack24.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack24.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack25 |
openbravo | openbravo_erp | 3.0:maintenance_pack25.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack25.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack26 |
openbravo | openbravo_erp | 3.0:maintenance_pack26.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack26.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack26.3 |
openbravo | openbravo_erp | 3.0:maintenance_pack26.4 |
openbravo | openbravo_erp | 3.0:maintenance_pack27 |
openbravo | openbravo_erp | 3.0:maintenance_pack27.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack28 |
openbravo | openbravo_erp | 3.0:maintenance_pack28.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack28.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack28.3 |
openbravo | openbravo_erp | 3.0:maintenance_pack28.4 |
openbravo | openbravo_erp | 3.0:maintenance_pack28.5 |
openbravo | openbravo_erp | 3.0:maintenance_pack29 |
openbravo | openbravo_erp | 3.0:maintenance_pack29.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack29.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack29.3 |
openbravo | openbravo_erp | 3.0:maintenance_pack29.4 |
openbravo | openbravo_erp | 3.0:maintenance_pack3 |
openbravo | openbravo_erp | 3.0:maintenance_pack3.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack3.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack30 |
openbravo | openbravo_erp | 3.0:maintenance_pack30.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack30.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack30.3 |
openbravo | openbravo_erp | 3.0:maintenance_pack31 |
openbravo | openbravo_erp | 3.0:maintenance_pack31.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack31.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack31.3 |
openbravo | openbravo_erp | 3.0:maintenance_pack31.4 |
openbravo | openbravo_erp | 3.0:maintenance_pack4 |
openbravo | openbravo_erp | 3.0:maintenance_pack4.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack4.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack5 |
openbravo | openbravo_erp | 3.0:maintenance_pack5.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack5.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack5.3 |
openbravo | openbravo_erp | 3.0:maintenance_pack6 |
openbravo | openbravo_erp | 3.0:maintenance_pack6.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack6.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack7 |
openbravo | openbravo_erp | 3.0:maintenance_pack7.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack7.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack7.3 |
openbravo | openbravo_erp | 3.0:maintenance_pack8 |
openbravo | openbravo_erp | 3.0:maintenance_pack8.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack8.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack8.3 |
openbravo | openbravo_erp | 3.0:maintenance_pack8.4 |
openbravo | openbravo_erp | 3.0:maintenance_pack9 |
openbravo | openbravo_erp | 3.0:maintenance_pack9.1 |
openbravo | openbravo_erp | 3.0:maintenance_pack9.2 |
openbravo | openbravo_erp | 3.0:maintenance_pack9.3 |
openbravo | openbravo_erp | 3.0:pr14q2 |
openbravo | openbravo_erp | 3.0:pr14q2.1 |
openbravo | openbravo_erp | 3.0:pr14q2.2 |
openbravo | openbravo_erp | 3.0:pr14q2.3 |
openbravo | openbravo_erp | 3.0:pr14q2.4 |
openbravo | openbravo_erp | 3.0:pr14q2.5 |
openbravo | openbravo_erp | 3.0:pr14q2.6 |
openbravo | openbravo_erp | 3.0:pr14q3 |
openbravo | openbravo_erp | 3.0:pr14q3.1 |
openbravo | openbravo_erp | 3.0:pr14q3.2 |
openbravo | openbravo_erp | 3.0:pr14q3.3 |
openbravo | openbravo_erp | 3.0:pr14q3.4 |
openbravo | openbravo_erp | 3.0:pr14q3.5 |
openbravo | openbravo_erp | 3.0:pr14q3.6 |
openbravo | openbravo_erp | 3.0:pr14q3.7 |
openbravo | openbravo_erp | 3.0:pr14q3.8 |
openbravo | openbravo_erp | 3.0:pr14q4 |
openbravo | openbravo_erp | 3.0:pr15q1 |
openbravo | openbravo_erp | 3.0:pr15q1.1 |
openbravo | openbravo_erp | 3.0:pr15q1.2 |
openbravo | openbravo_erp | 3.0:pr15q1.3 |
openbravo | openbravo_erp | 3.0:pr15q1.4 |
openbravo | openbravo_erp | 3.0:pr15q1.5 |
openbravo | openbravo_erp | 3.0:pr15q2 |
openbravo | openbravo_erp | 3.0:pr15q2.1 |
openbravo | openbravo_erp | 3.0:pr15q2.2 |
openbravo | openbravo_erp | 3.0:pr15q2.3 |
openbravo | openbravo_erp | 3.0:pr15q2.4 |
openbravo | openbravo_erp | 3.0:pr15q2.5 |
openbravo | openbravo_erp | 3.0:pr15q2.6 |
openbravo | openbravo_erp | 3.0:pr15q3 |
openbravo | openbravo_erp | 3.0:pr15q3.1 |
openbravo | openbravo_erp | 3.0:pr15q3.2 |
openbravo | openbravo_erp | 3.0:pr15q3.3 |
openbravo | openbravo_erp | 3.0:pr15q3.4 |
openbravo | openbravo_erp | 3.0:pr15q3.5 |
openbravo | openbravo_erp | 3.0:pr15q4 |
openbravo | openbravo_erp | 3.0:pr15q4.1 |
openbravo | openbravo_erp | 3.0:pr15q4.2 |
openbravo | openbravo_erp | 3.0:pr15q4.3 |
openbravo | openbravo_erp | 3.0:pr15q4.4 |
openbravo | openbravo_erp | 3.0:pr15q4.5 |
openbravo | openbravo_erp | 3.0:pr15q4.6 |
openbravo | openbravo_erp | 3.0:pr16q1 |
openbravo | openbravo_erp | 3.0:pr16q1.1 |
openbravo | openbravo_erp | 3.0:pr16q1.2 |
openbravo | openbravo_erp | 3.0:pr16q1.3 |
openbravo | openbravo_erp | 3.0:pr16q2 |
openbravo | openbravo_erp | 3.0:pr16q2.1 |
openbravo | openbravo_erp | 3.0:pr16q2.2 |
openbravo | openbravo_erp | 3.0:pr16q2.3 |
openbravo | openbravo_erp | 3.0:pr16q2.4 |
openbravo | openbravo_erp | 3.0:pr16q3 |
openbravo | openbravo_erp | 3.0:pr16q3.1 |
openbravo | openbravo_erp | 3.0:pr16q3.2 |
openbravo | openbravo_erp | 3.0:pr16q3.3 |
openbravo | openbravo_erp | 3.0:pr16q3.4 |
openbravo | openbravo_erp | 3.0:pr16q3.5 |
openbravo | openbravo_erp | 3.0:pr16q4 |
openbravo | openbravo_erp | 3.0:pr16q4.1 |
openbravo | openbravo_erp | 3.0:pr16q4.2 |
openbravo | openbravo_erp | 3.0:pr16q4.3 |
openbravo | openbravo_erp | 3.0:pr16q4.4 |
openbravo | openbravo_erp | 3.0:pr17q1 |
openbravo | openbravo_erp | 3.0:pr17q1.1 |
openbravo | openbravo_erp | 3.0:pr17q1.2 |
openbravo | openbravo_erp | 3.0:pr17q1.3 |
openbravo | openbravo_erp | 3.0:pr17q2 |
openbravo | openbravo_erp | 3.0:pr17q2.1 |
openbravo | openbravo_erp | 3.0:pr17q2.2 |
openbravo | openbravo_erp | 3.0:pr17q2.3 |
openbravo | openbravo_erp | 3.0:pr17q2.4 |
openbravo | openbravo_erp | 3.0:pr17q3 |
openbravo | openbravo_erp | 3.0:pr17q3.1 |
openbravo | openbravo_erp | 3.0:pr17q3.2 |
openbravo | openbravo_erp | 3.0:pr17q3.3 |
openbravo | openbravo_erp | 3.0:pr17q4 |
openbravo | openbravo_erp | 3.0:pr17q4.1 |
openbravo | openbravo_erp | 3.0:pr17q4.2 |
openbravo | openbravo_erp | 3.0:pr18q1 |
openbravo | openbravo_erp | 3.0:pr18q1.1 |
openbravo | openbravo_erp | 3.0:pr18q1.2 |
openbravo | openbravo_erp | 3.0:pr18q1.3 |
openbravo | openbravo_erp | 3.0:pr18q2 |
openbravo | openbravo_erp | 3.0:pr18q2.1 |
openbravo | openbravo_erp | 3.0:pr18q2.2 |
openbravo | openbravo_erp | 3.0:pr18q2.3 |
openbravo | openbravo_erp | 3.0:pr18q3 |
openbravo | openbravo_erp | 3.0:pr18q3.1 |
openbravo | openbravo_erp | 3.0:pr18q3.2 |
openbravo | openbravo_erp | 3.0:pr18q3.3 |
openbravo | openbravo_erp | 3.0:pr18q3.4 |
openbravo | openbravo_erp | 3.0:pr18q3.5 |
openbravo | openbravo_erp | 3.0:pr18q4 |
openbravo | openbravo_erp | 3.0:pr18q4.1 |
openbravo | openbravo_erp | 3.0:pr18q4.2 |
openbravo | openbravo_erp | 3.0:pr18q4.3 |
openbravo | openbravo_erp | 3.0:pr19q1 |
openbravo | openbravo_erp | 3.0:pr19q1.1 |
openbravo | openbravo_erp | 3.0:pr19q1.2 |
𝑥
= Vulnerable software versions
References